Vulnerabilities
13 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-54421 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.4 allows remote authenticated attackers to inject arbitrary web script or HTML via the default_keywords crafted parameter. This vulnerability is fixed in 2.2.4. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2025-32389 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refers to the structure `?param[0]=a¶m[1]=b¶m[2]=c` utilized by PHP, which is parsed by PHP as `$_GET['param']` being of type array. This issue has been patched in version 2.1.4. NVD description · AI analysis pending | 8.6 group max | <1% | PoC |
| — | |
| CVE-2025-22144 +1 in the same advisory: …22142 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromise another users password and take over their account. This issue has been addressed in release version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability. NVD description · AI analysis pending | 9.0 group max | <1% | PoC |
| — | |
| CVE-2022-2820 +1 in the same advisory: …2821 | Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2. NVD description · AI analysis pending | 8.2 group max | <1% | PoC |
| — |